[{"data":1,"prerenderedAt":29},["ShallowReactive",2],{"doc-en-block-ip-linux-vps":3},{"path":4,"slug":5,"title":6,"description":7,"category":8,"subcategory":9,"icon":10,"date":11,"author":12,"order":13,"image":14,"tags":15,"keywords":20,"docGroup":26,"docGroupIcon":26,"link_fr":27,"bodyHtml":28},"\u002Fdocs\u002Fen\u002Fvps\u002Fvps-linux\u002Fblock-ip-linux-vps","block-ip-linux-vps","How to Block an IP Address on Your Linux VPS","Block an IP address on your Winheberg VPS with UFW, firewalld, or iptables depending on your distribution, and learn how to identify suspicious IPs.","vps","vps-linux","tabler:file-text","2026-07-24","Winheberg",14,"\u002Fstatics\u002Fimages\u002Fdocs\u002Fen\u002Fvps-linux\u002Fblock-ip-linux-vps.webp",[8,16,17,18,19],"security","ufw","firewalld","iptables",[21,22,23,24,25],"block ip vps","ufw block ip address","firewalld rich rule","iptables drop ip","linux vps security","","\u002Fdocs\u002Fvps-linux\u002Fbloquer-ip-vps-linux","\u003Ch2>Context\u003C\u002Fh2>\n\u003Cp>You manage a \u003Cstrong>Winheberg VPS\u003C\u002Fstrong> and spotted a suspicious IP address in your logs? A bot spamming your contact form, a script trying to log in via SSH hundreds of times, or simply an unwanted visitor you want to keep out? Blocking an IP on your VPS is a \u003Cstrong>simple and effective\u003C\u002Fstrong> operation that takes less than a minute.\u003C\u002Fp>\n\u003Cp>This guide walks you through the three most common methods for blocking an IP on a Linux VPS, depending on the firewall installed on your system.\u003C\u002Fp>\n\u003Ch2>Prerequisites\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>An active \u003Cstrong>Winheberg VPS\u003C\u002Fstrong> with root SSH access\u003C\u002Fli>\n\u003Cli>The IP (or IP range) you want to block, identified in your logs\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>Which method should you choose based on your distribution?\u003C\u002Fh2>\n\u003Cp>The right tool depends on the firewall already installed on your VPS.\u003C\u002Fp>\n\u003Cdiv class=\"md-table md-table--striped\">\u003Cdiv class=\"md-table__caption\">Recommended firewall by distribution\u003C\u002Fdiv>\u003Cdiv class=\"md-table__scroll\">\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Distribution\u003C\u002Fth>\n\u003Cth>Recommended firewall\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\u003Ctr>\n\u003Ctd>Ubuntu\u003C\u002Ftd>\n\u003Ctd>UFW\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Debian\u003C\u002Ftd>\n\u003Ctd>UFW (installable)\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>AlmaLinux, Rocky Linux, Fedora\u003C\u002Ftd>\n\u003Ctd>firewalld\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>All distributions, including Alpine\u003C\u002Ftd>\n\u003Ctd>iptables\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\u003C\u002Ftable>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Cul>\n\u003Cli>\u003Cstrong>UFW\u003C\u002Fstrong> is the default firewall on \u003Cstrong>Ubuntu\u003C\u002Fstrong>, and the simplest to use. It&#39;s also easy to install on Debian\u003C\u002Fli>\n\u003Cli>\u003Cstrong>firewalld\u003C\u002Fstrong> is the default firewall on \u003Cstrong>AlmaLinux, Rocky Linux, and Fedora\u003C\u002Fstrong>. It offers advanced zone-based management\u003C\u002Fli>\n\u003Cli>\u003Cstrong>iptables\u003C\u002Fstrong> is the low-level tool that works \u003Cstrong>on every Linux distribution\u003C\u002Fstrong>, including \u003Cstrong>Alpine\u003C\u002Fstrong>. It&#39;s the universal solution if you don&#39;t want to install an extra firewall\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cdiv class=\"markdown-alert markdown-alert-tip\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cpath d=\"M12 16v-4\"\u002F>\u003Cpath d=\"M12 8h.01\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>Use the firewall already installed on your system rather than stacking several. Mixing UFW with manual iptables rules can create conflicts that are hard to diagnose.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>Block an IP based on your firewall\u003C\u002Fh2>\n\u003Cdiv class=\"md-tabs\" data-md-tabs>\u003Cdiv class=\"md-tabs__nav\" role=\"tablist\">\u003Cbutton type=\"button\" role=\"tab\" class=\"md-tabs__btn md-tabs__btn--active\" data-md-tab=\"0\" aria-selected=\"true\">UFW (Ubuntu, Debian)\u003C\u002Fbutton>\u003Cbutton type=\"button\" role=\"tab\" class=\"md-tabs__btn\" data-md-tab=\"1\" aria-selected=\"false\">firewalld (AlmaLinux, Rocky, Fedora)\u003C\u002Fbutton>\u003Cbutton type=\"button\" role=\"tab\" class=\"md-tabs__btn\" data-md-tab=\"2\" aria-selected=\"false\">iptables (all distributions, including Alpine)\u003C\u002Fbutton>\u003C\u002Fdiv>\u003Cdiv class=\"md-tabs__body\">\u003Cdiv role=\"tabpanel\" class=\"md-tab__panel md-tab__panel--active\" data-md-panel=\"0\">\u003Cp>UFW (\u003Cem>Uncomplicated Firewall\u003C\u002Fem>) is by far the simplest solution. The syntax is clear and readable.\u003C\u002Fp>\n\u003Ch3>Install UFW (if not already done)\u003C\u002Fh3>\n\u003Cp>On Ubuntu, UFW is usually already installed. On Debian, add it with this command.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">apt install ufw -y\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch3>Block a single IP\u003C\u002Fh3>\n\u003Cp>To block a specific IP address.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">ufw deny from 203.0.113.42\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Replace \u003Ccode>203.0.113.42\u003C\u002Fcode> with the IP you want to block. The rule applies immediately.\u003C\u002Fp>\n\u003Ch3>Block an entire IP range\u003C\u002Fh3>\n\u003Cp>If you want to block a whole block (for example, an entire range used by an attacker), use CIDR notation.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">ufw deny from 203.0.113.0\u002F24\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>This command blocks the 256 addresses from \u003Ccode>203.0.113.0\u003C\u002Fcode> to \u003Ccode>203.0.113.255\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Ch3>Block an IP on a specific port only\u003C\u002Fh3>\n\u003Cp>If you want to block an IP only for a specific service (for example, blocking SSH access but leaving port 80 open).\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">ufw deny from 203.0.113.42 to any port 22\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch3>Check active rules\u003C\u002Fh3>\n\u003Cp>To see all the UFW rules currently in place.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">ufw status numbered\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>You&#39;ll see something like this.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>Status: active\n\n     To                         Action      From\n     --                         ------      ----\n[ 1] Anywhere                   DENY        203.0.113.42\n[ 2] 22\u002Ftcp                     ALLOW       Anywhere\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch3>Remove a blocking rule\u003C\u002Fh3>\n\u003Cp>To remove a rule, use its number.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">ufw delete 1\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Or directly by specifying the IP.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">ufw delete deny from 203.0.113.42\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003C\u002Fdiv>\u003Cdiv role=\"tabpanel\" class=\"md-tab__panel\" data-md-panel=\"1\" hidden>\u003Cp>firewalld is the default firewall in the Red Hat ecosystem. It works with zones and rich rules for IP filtering.\u003C\u002Fp>\n\u003Ch3>Block a single IP\u003C\u002Fh3>\n\u003Cp>To block an IP address with firewalld, you use a rich rule.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">firewall-cmd --permanent --add-rich-rule=&#39;rule family=&quot;ipv4&quot; source address=&quot;203.0.113.42&quot; reject&#39;\nfirewall-cmd --reload\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The \u003Ccode>--permanent\u003C\u002Fcode> option makes the rule persist across reboots. \u003Ccode>firewall-cmd --reload\u003C\u002Fcode> applies the changes.\u003C\u002Fp>\n\u003Ch3>Block an entire IP range\u003C\u002Fh3>\n\u003Cp>To block a full CIDR block.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">firewall-cmd --permanent --add-rich-rule=&#39;rule family=&quot;ipv4&quot; source address=&quot;203.0.113.0\u002F24&quot; reject&#39;\nfirewall-cmd --reload\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch3>Block an IP on a specific port only\u003C\u002Fh3>\n\u003Cp>To block an IP only on the SSH port (22).\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">firewall-cmd --permanent --add-rich-rule=&#39;rule family=&quot;ipv4&quot; source address=&quot;203.0.113.42&quot; port port=&quot;22&quot; protocol=&quot;tcp&quot; reject&#39;\nfirewall-cmd --reload\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch3>Check active rules\u003C\u002Fh3>\n\u003Cp>To see all the rich rules currently in place.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">firewall-cmd --list-rich-rules\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch3>Remove a blocking rule\u003C\u002Fh3>\n\u003Cp>To remove a rule, use \u003Ccode>--remove-rich-rule\u003C\u002Fcode> with the exact same syntax used to add it.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">firewall-cmd --permanent --remove-rich-rule=&#39;rule family=&quot;ipv4&quot; source address=&quot;203.0.113.42&quot; reject&#39;\nfirewall-cmd --reload\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cdiv class=\"markdown-alert markdown-alert-tip\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cpath d=\"M12 16v-4\"\u002F>\u003Cpath d=\"M12 8h.01\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>\u003Ccode>reject\u003C\u002Fcode> sends an error packet back to the sender, while \u003Ccode>drop\u003C\u002Fcode> silently ignores the packets. \u003Ccode>drop\u003C\u002Fcode> is generally preferable against attackers, so you don&#39;t confirm to them that the port is filtered.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003C\u002Fdiv>\u003Cdiv role=\"tabpanel\" class=\"md-tab__panel\" data-md-panel=\"2\" hidden>\u003Cp>\u003Ccode>iptables\u003C\u002Fcode> is the low-level Linux firewall management tool. It works on every distribution with no extra install, except on Alpine where it needs to be installed.\u003C\u002Fp>\n\u003Ch3>On Alpine, install iptables\u003C\u002Fh3>\n\u003Cpre>\u003Ccode class=\"language-bash\">apk add iptables\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch3>Block a single IP\u003C\u002Fh3>\n\u003Cp>To block an incoming IP address.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">iptables -A INPUT -s 203.0.113.42 -j DROP\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The \u003Ccode>DROP\u003C\u002Fcode> action silently ignores packets coming from this IP. To send an error back to the sender, use \u003Ccode>REJECT\u003C\u002Fcode> instead.\u003C\u002Fp>\n\u003Ch3>Block an entire IP range\u003C\u002Fh3>\n\u003Cpre>\u003Ccode class=\"language-bash\">iptables -A INPUT -s 203.0.113.0\u002F24 -j DROP\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch3>Block an IP on a specific port only\u003C\u002Fh3>\n\u003Cp>To block an IP only on the SSH port.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">iptables -A INPUT -s 203.0.113.42 -p tcp --dport 22 -j DROP\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch3>Check active rules\u003C\u002Fh3>\n\u003Cpre>\u003Ccode class=\"language-bash\">iptables -L INPUT -n -v --line-numbers\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>You&#39;ll see something like this.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>Chain INPUT (policy ACCEPT)\nnum   pkts bytes target     prot opt in     out     source               destination\n1        0     0 DROP       all  --  *      *       203.0.113.42         0.0.0.0\u002F0\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch3>Remove a blocking rule\u003C\u002Fh3>\n\u003Cp>To remove a rule, use its line number (visible with \u003Ccode>--line-numbers\u003C\u002Fcode>).\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">iptables -D INPUT 1\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch3>Make the rules persistent\u003C\u002Fh3>\n\u003Cp>By default, iptables rules are lost on reboot. To keep them, you need to save them.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>On Debian and Ubuntu\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">apt install iptables-persistent -y\nnetfilter-persistent save\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>\u003Cstrong>On AlmaLinux, Rocky Linux, and Fedora\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>If you&#39;re using iptables instead of firewalld, install the save service.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">dnf install iptables-services -y\nservice iptables save\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>\u003Cstrong>On Alpine Linux\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">\u002Fetc\u002Finit.d\u002Fiptables save\nrc-update add iptables\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cdiv class=\"markdown-alert markdown-alert-important\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Cpath d=\"M12 22c5.523 0 10-4.477 10-10S17.523 2 12 2 2 6.477 2 12s4.477 10 10 10z\"\u002F>\u003Cpath d=\"M12 8v4\"\u002F>\u003Cpath d=\"M12 16h.01\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>If you don&#39;t save the rules, your blocks will disappear on the VPS&#39;s next reboot.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>How do you find the IP to block?\u003C\u002Fh2>\n\u003Cp>Before blocking an IP, you first need to know which one to block. Here are the most common sources.\u003C\u002Fp>\n\u003Ch3>In the SSH logs\u003C\u002Fh3>\n\u003Cp>To see recent SSH connection attempts and identify malicious IPs.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\"># Debian, Ubuntu\njournalctl -u ssh -n 100 | grep &quot;Failed password&quot;\n\n# AlmaLinux, Rocky, Fedora\njournalctl -u sshd -n 100 | grep &quot;Failed password&quot;\n\n# Alpine\ntail -n 100 \u002Fvar\u002Flog\u002Fmessages | grep &quot;Failed password&quot;\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch3>In a web server&#39;s logs\u003C\u002Fh3>\n\u003Cp>To identify IPs spamming your site (Nginx as an example).\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">tail -n 1000 \u002Fvar\u002Flog\u002Fnginx\u002Faccess.log | awk &#39;{print $1}&#39; | sort | uniq -c | sort -rn | head\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>This command shows the 10 most active IPs over the last 1000 requests. An IP showing up hundreds of times is likely a bot or an attacker.\u003C\u002Fp>\n\u003Ch3>Checking an IP&#39;s reputation\u003C\u002Fh3>\n\u003Cp>Before blocking, you can check an IP&#39;s reputation on online services like \u003Ca href=\"https:\u002F\u002Fwww.abuseipdb.com\u002F\">AbuseIPDB\u003C\u002Fa> or \u003Ca href=\"https:\u002F\u002Fwww.virustotal.com\u002F\">VirusTotal\u003C\u002Fa>. If the IP has been reported by many users, blocking it is generally justified.\u003C\u002Fp>\n\u003Cdiv class=\"markdown-alert markdown-alert-warning\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Cpath d=\"M10.29 3.86L1.82 18a2 2 0 0 0 1.71 3h16.94a2 2 0 0 0 1.71-3L13.71 3.86a2 2 0 0 0-3.42 0z\"\u002F>\u003Cline x1=\"12\" y1=\"9\" x2=\"12\" y2=\"13\"\u002F>\u003Cline x1=\"12\" y1=\"17\" x2=\"12.01\" y2=\"17\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>These services aren&#39;t foolproof. An IP can be wrongly flagged, or may have been used by an attacker in the past and later reassigned to a legitimate user (a common case with dynamic ISP IPs, shared VPNs, or Tor exit nodes). Before blocking an entire range, check your own logs to confirm the IP actually shows suspicious behavior on your end. Don&#39;t rely solely on AbuseIPDB to decide on a block.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>A more automated approach, CrowdSec\u003C\u002Fh2>\n\u003Cp>If you want to automatically block IPs attacking your server, without having to hunt them down by hand, we recommend installing \u003Cstrong>CrowdSec\u003C\u002Fstrong>. It analyzes logs in real time, detects malicious behavior, and blocks IPs automatically. It&#39;s also a modern alternative to Fail2Ban.\u003C\u002Fp>\n\u003Cp>To learn more, check our guide on securing a Linux VPS, which covers the full CrowdSec installation.\u003C\u002Fp>\n\u003Ch2>Need help?\u003C\u002Fh2>\n\u003Cp>If you accidentally blocked your own IP (yes, it happens 😅) and can no longer connect to your VPS, our team is here. Open a ticket in the \u003Cstrong>Technical\u003C\u002Fstrong> department from your client area and fill in the \u003Cstrong>Related Product\u003C\u002Fstrong> field with the VPS in question, we can help you access your server through the rescue console to undo the block.\u003C\u002Fp>\n\u003Cp>You now know how to block an IP on your Linux VPS, whatever your system 🛡️\u003C\u002Fp>\n",1788993143856]